CVE Database /
CVE-2022-3881
CVE · Medium
CVE-2022-3881 — WP Tools Debug Log, Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log [wptools] < 3.43 (closed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-3881
|
WP Tools Debug Log, Repair, Javascript errors, Jquery errors, Increase Maximum Limits, File Permissions, Transients, Error Log [wptools] < 3.43 (closed) |
Cross-Site Request Forgery (CSRF) |
Medium
5.7
|
< 3.43
|
3.43 |
2022-11-18 |
—
|
CVE-2022-3881
The WP Tools plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the wptools_install_plugin() function in versions up to, and including, 3.42. This makes it possible for authenticated attackers with minimal permission, such as a subscriber, to install other plugins owned by the developer on the vulnerable site. This could be used to install additional vulnerable plugins that could aid in further compromise of the site.
Source:
Wordfence
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings